DORA governance combines national competent authority supervision, ESA cross-sector coordination, and Joint Oversight Mechanism for CTPPs. Penalties set by Member States; supervisory powers include withdrawal of authorization for severe non-compliance.
National competent authorities
Member States designate competent authorities per financial sector:
- Banking: typically banking supervisor (DE: BaFin; FR: ACPR; IT: Banca d'Italia).
- Securities: securities authority (DE: BaFin; FR: AMF; IT: CONSOB).
- Insurance: insurance supervisor (DE: BaFin; FR: ACPR; IT: IVASS).
- Other sectors: per Member State structure.
National competent authorities exercise day-to-day supervision over financial entities. Coordinated with ESAs for cross-cutting issues.
ESAs (Joint Committee for DORA)
EBA, ESMA, EIOPA cooperate via Joint Committee on DORA matters. Tasks:
- Develop RTS / ITS jointly.
- Designate CTPPs.
- Coordinate Lead Overseer assignments.
- Issue cross-sector guidelines.
- Cooperate with ENISA and Cooperation Group on NIS2 interactions.
Joint Oversight Mechanism for CTPPs
Lead Overseer
For each CTPP, one ESA designated as Lead Overseer based on:
- Sector concentration in CTPP's financial-entity customer base.
- ESA expertise.
- ESA discretion.
Lead Overseer:
- Conducts ongoing oversight of CTPP.
- Issues recommendations.
- Cooperates with other ESAs via Joint Oversight Network.
- Can impose periodic penalty payments.
Joint Oversight Network
ESAs + Member State competent authorities collaborating on CTPP oversight:
- Joint examinations.
- Information sharing.
- Coordinated supervisory actions.
Powers (Articles 35-39)
Lead Overseer can:
- Request information from CTPP.
- Conduct general investigations.
- Conduct on-site inspections at CTPP premises.
- Issue recommendations.
- Impose periodic penalty payments (Article 35(6)) — up to 1% of average daily worldwide turnover of preceding business year, per day of non-compliance, for up to six months.
CTPP non-cooperation can trigger recommendation that financial entities terminate or modify CTPP relationships — commercial pressure on CTPP.
Supervision of financial entities (Articles 50-56)
National competent authorities supervise financial entities' DORA compliance:
- Information requests (Article 50).
- General investigations (Article 51).
- On-site inspections (Article 52).
- Pre-emptive measures (Article 53) — to prevent imminent serious damage.
- Corrective measures (Article 54) — orders, restrictions.
- Withdrawal of authorization (Article 56) for severe non-compliance.
Supervision is risk-based and proportional.
Penalties
DORA does not set EU-wide penalty caps. Member States establish penalties per national law (Article 50(5)).
Penalties must be:
- Effective
- Proportionate
- Dissuasive
Member State implementations vary. Typical penalty types:
- Administrative fines — varies by Member State, sector-specific limits.
- Withdrawal of authorization — for severe / repeated violations.
- Public statements identifying violations.
- Cease-and-desist orders.
- Periodic penalty payments.
- Personal liability of management body members (some Member States).
DE BaFin penalties under DORA — administered through existing BaFin enforcement framework (KWG, ZAG, VAG, WpHG depending on sector).
CTPP periodic penalty payments
Lead Overseer can impose periodic penalty payments on CTPPs:
- Daily fines.
- Up to 1% of average daily worldwide turnover (preceding business year).
- For up to six months.
This is the EU-level enforcement tool against non-cooperative CTPPs. Practical impact significant given large cloud / SaaS provider revenue.
Management body responsibility
Article 5 requires management body responsibility for ICT risk management framework. Combined with Member State personal liability provisions, management body members face real exposure.
Cooperation with other regimes
DORA authorities cooperate with:
- GDPR DPAs for personal data breach overlap.
- NIS2 authorities for non-financial cybersecurity overlap.
- AI Act AI Office for AI feature obligations.
- Member State criminal prosecutors where criminal aspects arise.
- Other Member State authorities for cross-border matters.
Coordination guidance still maturing; first year of enforcement shaping practice.
SRE and AI-agent fit notes
Management body training in financial-AI context
Financial-entity management body training under DORA should include:
- AI feature dependencies (foundation models, vendor concentration)
- AI-specific threat awareness
- AI-related TPP risks
- AI-system incident response
CTPP designation implications for AI vendors
If Anthropic, OpenAI, Google, or other AI providers reach CTPP designation thresholds:
- Lead Overseer oversight added.
- Commercial terms with financial customers may shift.
- Audit cooperation obligations on the AI vendor.
- Potential for periodic penalty payments if non-cooperative.
Stefan-context implementation sketch
- For financial-services engagements: support client governance maturation under DORA.
- For potential CTPP-status AI vendors: anticipate evolving commercial landscape.